{"id":"CVE-2025-24472","title":"An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…","summary":"An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior k…","severity":"high","cvss":8.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-288"],"vendor":"fortinet","product":"fortiproxy","affected":["fortiproxy >= 7.0.0, < 7.0.20","fortiproxy >= 7.2.0, < 7.2.13","fortios >= 7.0.0, < 7.0.17"],"patched":["fortiproxy 7.2.13","fortios 7.0.17"],"published":"2025-02-11","updated":"2026-07-08","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-24472","references":[{"url":"https://fortiguard.fortinet.com/psirt/FG-IR-24-535","label":"psirt@fortinet.com"},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-24472","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","kev","in-the-wild","exploit-available"],"epss":0.07235,"epssPercentile":0.94047,"kev":true,"kevDateAdded":"2025-03-18","kevDueDate":"2025-04-08","kevRansomware":true,"exploited":true,"ingestedAt":"2026-07-08T14:51:15.616Z","exploits":{"github":1,"githubRepos":["https://github.com/razureink/cve-2025-24472-fortinet_authbypass_reproduction"],"checkedAt":"2026-09-23T07:13:35.198Z"},"exploitAvailable":true,"slug":"CVE-2025-24472","body":"## Overview\n\nAn Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote unauthenticated attacker with prior knowledge of upstream and downstream devices serial numbers to gain super-admin privileges on the downstream device, if the Security Fabric is enabled, via crafted CSF proxy requests.\n\n## Affected\n\n- `fortiproxy >= 7.0.0, < 7.0.20`\n- `fortiproxy >= 7.2.0, < 7.2.13`\n- `fortios >= 7.0.0, < 7.0.17`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `fortiproxy 7.2.13`\n- `fortios 7.0.17`","depth":"abyssal","depthScore":76,"depthScoreParts":{"impact":44.6,"likelihood":1.4,"exploitation":25,"ransomware":5},"changes":[{"seq":4797,"id":"CVE-2025-24472","ts":1788887207215,"field":"exploit_available","old":"false","new":"true"},{"seq":3680,"id":"CVE-2025-24472","ts":1788886324273,"field":"exploit_available","old":"true","new":"false"},{"seq":2527,"id":"CVE-2025-24472","ts":1788883002826,"field":"exploit_available","old":"false","new":"true"},{"seq":1556,"id":"CVE-2025-24472","ts":1788882405475,"field":"exploit_available","old":"true","new":"false"},{"seq":670,"id":"CVE-2025-24472","ts":1788881843260,"field":"exploit_available","old":"false","new":"true"}]}